Lead Generation
Apollo.io
Rest of world Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by ZenLeads Inc. · www.apollo.io
Compare with Lusha → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Apollo.io, sold by ZenLeads Inc. d/b/a Apollo.io of Covina, California, is a lead-generation platform combining a 240M+ contact, 30M+ account database with built-in sequencing. It scored strongest on pricing transparency at 5-7: all four tiers, per-seat prices, credit allowances and add-ons are public, though what a credit buys per data type sits on a separate page. CRM sync and export followed at 4-6, crediting named Salesforce, HubSpot and Pipedrive integrations and a perpetual license to contact data incorporated during the term. Data coverage is the weak spot at a flat 3: a headline count with no per-country breakdown behind it, and terms disclaiming accuracy, completeness and currency. Visitor identification and sovereignty trail, with no public information on how tracking works or on EU hosting behind a US contracting entity with an EEA representative. Scores span 4-6 on data provenance: higher scores credit the plainly disclosed contributory collection, lower ones weigh the absence of any published lawful basis for EU records.
Speaks for it
- Pricing transparency scored 5-7: tiers from a $0 plan to $49, $79 and $119 per seat per month billed annually (the $119 tier carries a three-seat minimum) are public with credit allowances, alongside add-ons at $119 per team, per month billed annually.
- The terms grant a perpetual, worldwide, transferable, royalty-free license to Business Contact Information incorporated into your own systems during the subscription term.
- CRM sync and export scored 4-6, on named Salesforce, HubSpot and Pipedrive integrations, waterfall enrichment and a documented API.
- Contributory collection is disclosed plainly, with a separate Article 14 Processing Notice, a self-service removal page and a suppression list against re-adding.
- The $0 plan requires no credit card and carries 900 credits per seat per year, granted monthly.
Held against it
- Data coverage scored 3 with no spread: 240M+ contacts and 30M+ accounts stand as headline counts with no public per-country breakdown, verification method or refresh cadence.
- Terms disclaim accuracy, completeness and currency of the data, while subscriptions are non-cancelable during the term and all payments are nonrefundable.
- Visitor identification scored 2-3, with no public information on how the tracking script works, whether it sets cookies, or on a consent-mode or cookieless option.
- Sovereignty scored 3-4: ZenLeads Inc. of Covina, California may collect, process, store and transfer personal information in the United States and other countries, and we found no public information on EU hosting.
- Prospecting compliance scored 3-4, and we found no public information on country-aware flags, do-not-call register checks, or the lawful basis for EU records.
Best for
- You need tier prices, credit allowances and post-cancellation data rights in writing before you sign.
- Your stack runs on Salesforce, HubSpot or Pipedrive and you want API-based enrichment with a stated perpetual license to incorporated contact data.
- You want to test before paying, with the $0 plan's 900 credits per seat per year granted monthly and no credit card required.
Avoid if
- Your procurement requires an EU contracting entity or EU hosting — the contracting entity is ZenLeads Inc. of Covina, California.
- You need the vendor to warrant data accuracy or refund bad records — the terms disclaim accuracy, completeness and currency, and make all payments nonrefundable.
- Your outbound team needs vendor-side compliance handling — the terms prohibit use that violates marketing laws such as CAN-SPAM, CASL or TCPA and leave the compliance risk with the customer.
- You cannot accept that data your team submits may grow the Contributor Database sold to other customers.
The scores
Coverage, accuracy & freshness
Show reasoningHide reasoning
How this is scored
How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.
0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.
3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.
5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.
8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.
10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.
The SDR Team Lead
240M+ contacts and 30M+ accounts is a headline number with nothing behind it for my region: no per-country or DACH coverage, and "Data refresh that improves over time" states no verification method or cadence. The terms expressly disclaim any warranty of accuracy, completeness or currency of the data, and subscriptions are nonrefundable — every bounced email is my team's cost, not the vendor's. 1 4
The RevOps Manager
Headline counts of 240 million contacts and 30 million accounts are the only coverage statement, with nothing per country or region and nothing on DACH, and "data refresh that improves over time" is not a cadence. The terms expressly disclaim accuracy, completeness and currency of the data while subscriptions are non-refundable, so inaccuracy stays the buyer's cost. I found no public information on a verification method or a bounce guarantee. 1 4
The Data Protection Officer
The headline is 240M+ contacts and 30M+ accounts with "data refresh that improves over time" and "verified emails" on the Chrome extension, but we found no public information on coverage by country or region, no re-verification cadence and no method behind the word verified. The terms expressly disclaim any warranty of accuracy, completeness or currency of the data, compiled from "various third-party sources". That is a headline count with nothing verifiable behind it. 1 4
The ABM Marketer
240M+ contacts and 30M+ accounts is a headline figure with no country, industry or DACH breakdown, and beyond "Data refresh that improves over time" I found no public information on verification method or refresh cadence. The terms state that accuracy, completeness and currency are not warranted and that subscriptions are nonrefundable, so a bad record is my cost, not the vendor's. 1 4
The DACH Sales Director
The homepage claims 240M+ contacts and 30M+ accounts — a headline count for the whole database — and I found no public information breaking coverage out for Germany, Austria or Switzerland, no verification method beyond the marketing word "verified", and only "Data refresh that improves over time" on upkeep. The terms expressly disclaim accuracy and make all payments nonrefundable, so the cost of bad data sits with the buyer, not the vendor. 1 4
The Skeptic
240M contacts and 30M accounts is a headline count with nothing behind it — we found no public information on per-country coverage, verification method, or how often records are re-verified, beyond "Data refresh that improves over time". The terms run in the opposite direction from a guarantee: Apollo expressly represents neither accuracy nor currency of any data, and refunds for partially used service units are excluded. 1 4
Data sources & lawful basis
Show reasoningHide reasoning
How this is scored
Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.
0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.
3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.
5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.
8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.
10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.
The SDR Team Lead
Sources are named in general and contributory terms — a proprietary Contributor Database grown from data customers submit through the service, with an Article 14 Processing Notice, a removal page and a suppression list that keeps removed people from being re-added. We found no public information on a legitimate-interest assessment for EU records, per-record source traceability, or different handling of EU versus US records. 3 4
The RevOps Manager
The privacy policy does disclose where the data comes from — a Contributor Database grown from customer-submitted data — alongside a separate Article 14 processing notice, a removal page and a suppression list to keep removed people from re-entering. But GDPR compliance is asserted as a homepage badge, and I found no public statement of the legal basis for processing these records and no legitimate-interest balancing. Contributor-sourced collection is at least disclosed as such. 1 3 4
The Data Protection Officer
Contributory collection is disclosed as such — customer-submitted data may be used to grow, enrich and verify the Contributor Database sold to other customers — and there is a separate Article 14 Processing Notice, a self-service Removal Page and a suppression list to keep removed people from being re-added. But we found no public information naming the legal basis for EU records, no legitimate-interest statement or balancing, and no per-record source or collection date; "GDPR Compliant" appears as a review-page badge with nothing behind it. 2 3 4
The ABM Marketer
The contributory model is disclosed plainly — customer-submitted data grows the Contributor Database that is sold on to other customers — and there is a separate Article 14 Processing Notice, a self-service removal page and a suppression list to stop records being re-added. What I found no public information on is the lawful basis: no legitimate-interest statement or balancing appears anywhere in the captured pages for EU records. 3 4
The DACH Sales Director
The Contributor Database is disclosed as grown from customers' own submitted data and resold onward, with a dedicated Article 14 Processing Notice for the people in it, a self-service removal page and a suppression list to prevent re-adding — more transparency about contributory collection than most US vendors show. But we found no public information on the legal basis or a balancing test for EU records, and the data is described only as compiled from various third-party sources with registers unnamed. 3 4
The Skeptic
Contributory collection is disclosed in plain words — customer-submitted data grows, enriches and verifies the Contributor Database that is then sold to other customers — and an Article 14 Processing Notice, a self-service Removal Page and a suppression list all exist. But sources beyond "various third-party sources" and contributors go unnamed, and we found no public statement of the legal basis for EU records, no legitimate-interest balancing, and no per-record provenance. 3 4
Visitor identification & intent signals
Show reasoningHide reasoning
How this is scored
Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.
0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.
3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.
5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.
8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.
10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.
The SDR Team Lead
Company-level identification is on the price list — the Inbound add-on at $119 Per team, per month billed annually, identifying up to 50,000 companies per month — and buying signals include intent, job changes and website visits. Beyond that, we found no public information on how the tracking works, whether the script needs consent where it sets cookies, any cookieless option, or where the intent data comes from. 2 1
The RevOps Manager
Company identification is sold as an Inbound add-on with a cap of 50,000 identified companies per month, and "intent" appears as a buying signal with no source named. I found no public information on how the tracking works, whether the script sets cookies, its behaviour without consent under German tracking law, or any consent-mode or cookieless option. 1 2
The Data Protection Officer
Visitor identification is sold as an Inbound add-on identifying up to 50,000 companies per month, with intent, job changes and website visits among the buying signals. We found no public information on how the tracking works, whether the script sets cookies, any consent-mode or cookieless option, or any position on consent under §25 TDDDG — for a DACH buyer the script may fire before consent and nothing published says otherwise. 1 2
The ABM Marketer
Company-level identification exists and is priced publicly — the Inbound add-on at $119 per team, per month billed annually, identifies up to 50,000 companies per month — with intent, job changes and website visits named as buying signals. I found no public information on how the tracking script works, whether it needs consent under the German cookie rule, any cookieless option, the source of the intent data, or how an alert reaches the account owner. 1 2
The DACH Sales Director
Website visitor identification and buying signals such as intent, job changes and website visits appear on the homepage, and the Inbound add-on prices identification at up to 50,000 companies per month — company-level, so at least not person-level. We found no public information on how the identification works, on a cookieless option, or on consent under the German TDDDG, which is the first thing a DPO will ask. 1 2
The Skeptic
Visitor identification is sold as an Inbound add-on identifying up to 50,000 companies per month, and intent and website visits appear as buying signals — but we found no public information on how the tracking works, whether the script sets cookies or requires consent under the German telemedia rules, on cookieless operation, or on where the intent data comes from. 1 2
Prospecting workflow & outreach rules
Show reasoningHide reasoning
How this is scored
Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.
0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.
3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.
5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.
8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.
10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.
The SDR Team Lead
The homepage promises tools to comply with GDPR, CAN-SPAM and DNC, agents with built-in consent and opt-out rules, and call-recording consent where required — but the terms make the customer responsible for not violating marketing laws, which leaves German cold-outreach risk sitting on my reps. We found no public information on country-aware flags for German contacts, checks against national do-not-call registers, or guidance on cold outreach rules in EU markets. 1 4
The RevOps Manager
The homepage promises "all the tools you need to comply with GDPR, CAN-SPAM, DNC and regional regulations" and sequences carry consent and opt-out support, but that is marketing breadth rather than workflow. The terms make marketing-law compliance the customer's obligation, and I found no public information on country-aware flags for German contacts, checks against national do-not-call registers, or a do-not-contact list shared across exports. 1 4
The Data Protection Officer
Sequences advertise "built-in support for consent and opt-out rules" and the marketing names GDPR, CAN-SPAM and DNC tooling, while the terms prohibit use that violates CAN-SPAM, CASL or TCPA. We found no public information on country-aware handling for German contacts under UWG §7, on checking numbers against national do-not-call registers, or on a suppression list shared across every export — the compliance risk sits with the customer. 1 4
The ABM Marketer
The homepage claims "all the tools you need to comply with GDPR, CAN-SPAM, DNC and regional regulations" and agents with built-in consent and opt-out support, but no mechanism is described on the captured pages, and the terms make marketing-law violations a prohibited use — the legal risk sits with me. I found no public information on country-aware flags for German contacts, checks against national do-not-call registers, or guidance on cold outreach rules in the main EU markets. 1 4
The DACH Sales Director
The homepage promises "all the tools you need to comply with GDPR, CAN-SPAM, DNC and regional regulations" and the terms prohibit marketing-law violations — two of the three named regimes are American, and the legal risk stays contractually with me. A Parallel Dialer that multiplies outbound volume is exactly the tool a German rep must not aim at contacts without consent under UWG §7, and we found no public information on do-not-call register checks, country-aware flags or a shared suppression list. 1 2 4
The Skeptic
The homepage promises "all the tools you need to comply with GDPR, CAN-SPAM, DNC" and agents with built-in consent and opt-out support, but the only concrete mechanism on the captured pages is a terms clause obliging the customer not to violate CAN-SPAM, CASL or TCPA — the risk sits with the buyer. We found no public information on do-not-contact suppression inside the workflow, checks against do-not-call registers, or country-aware flags for German contacts. 1 4 2
CRM sync, enrichment & export
Show reasoningHide reasoning
How this is scored
Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.
0 — Manual CSV export only; no CRM integration and no API.
3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.
5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.
8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.
10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.
The SDR Team Lead
Named integrations with Salesforce, HubSpot and Pipedrive, waterfall enrichment, a documented API with usage limits and 200+ integrations cover how the data reaches my stack. Exit terms are unusually plain — a perpetual, transferable license to contact data already incorporated into our systems, while uploaded data may be destroyed on termination — but we found no public information on bidirectional re-enrichment or propagation of objections into synced records. 2 1 4
The RevOps Manager
Named integrations with Salesforce, HubSpot and Pipedrive, a documented API, and — to their credit — exit terms that say plainly what I may keep: a perpetual licence to contact data incorporated into my own systems during the term, while my uploaded data may be destroyed. I found no public information on field mapping, deduplication, scheduled re-enrichment, or whether an objection from a contact propagates back into synced records. And syncing cuts both ways: customer-submitted data may be used to grow the very database sold to other customers. 1 2 4
The Data Protection Officer
There are named integrations with Salesforce, HubSpot and Pipedrive, waterfall enrichment, an API with published documentation, and — the part I care about — an explicit exit position: a perpetual, transferable license to Business Contact Information incorporated into the buyer's own records during the subscription term. We found no public information on field mapping, deduplication, bidirectional sync, or whether an objection or deletion by a person propagates into the synced CRM records; from the moment of export the customer is the controller with no documented lineage. 1 2 4
The ABM Marketer
Salesforce, HubSpot and Pipedrive integrations, waterfall enrichment, a documented API and 200+ integrations are all on the pages, and the exit terms are unusually clear: contacts I incorporate into my own CRM during the term carry a perpetual, royalty-free license even after termination. I found no public information on field mapping, deduplication, bidirectional sync, or whether a contact's objection propagates back into my synced records. 1 2 4
The DACH Sales Director
CRM integrations with Salesforce, HubSpot and Pipedrive are named, waterfall enrichment is included from Basic upward, an API with documentation exists, and the terms grant a perpetual licence to Business Contact Information incorporated into my own systems — so what I may keep after cancellation is stated plainly. We found no public information on field mapping, deduplication, bidirectional sync, or whether a data subject's objection propagates back into synced CRM records. 1 2 4
The Skeptic
Named CRM integrations with Salesforce, HubSpot and Pipedrive, waterfall enrichment, a documented API whose usage limits the terms reference, and — unusually plainly — a perpetual, transferable license to exported contact data incorporated during the term, with retention after termination stated. We found no public information on field mapping, deduplication, bidirectional sync, scheduled re-enrichment, or propagation of deletions when a person objects. 1 2 4
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.
3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.
5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.
8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.
The SDR Team Lead
The contracting entity is ZenLeads Inc. of Covina, California, which may collect, process, store and transfer personal information "in the United States and other countries", with an EEA representative, Standard Contractual Clauses and EU-US Data Privacy Framework certification as the transfer basis. That is a US vendor with a European representative and a transfer mechanism — no EU contracting entity, no EU hosting, and the subprocessor list gives no residency comfort. 3 4
The RevOps Manager
The contracting entity is ZenLeads Inc. of Covina, California, processing personal information "in the United States and other countries", with Lionheart Squared as the EEA representative and HelloDPO as UK/EEA DPO, relying on the Data Privacy Framework and standard contractual clauses for transfers. I found no public information pointing to an EU contracting entity or EU hosting, so this sits at the non-EU vendor with an Article 27 representative. A subprocessor list does exist. 3 4
The Data Protection Officer
The contracting entity is ZenLeads Inc. of Covina, California, which may collect, process, store and transfer personal information in the United States and other countries, with Lionheart Squared as the Article 27 EEA representative, HelloDPO for the UK and as DPO, transfers resting on Standard Contractual Clauses and Data Privacy Framework certification, and a subprocessor list referenced. This is the non-EU-entity-with-a-representative pattern; we found no public information on EU hosting for the database of European business contacts or on where the data partners sit. 3 4
The ABM Marketer
The contracting entity is ZenLeads Inc. of Covina, California with an EEA representative and a UK representative who also serves as DPO — the US vendor with an Article 27 representative setup — and processing is US-based, with transfers named under Standard Contractual Clauses and the EU-US Data Privacy Framework. A subprocessor list is said to be available, but the captured pages show no EU contracting entity or EU hosting, and I found no public information on where enrichment or AI processing happen. 3 4
The DACH Sales Director
The contracting entity is ZenLeads Inc. of Covina, California, processing personal information "in the United States and other countries", with Lionheart Squared as representative in the EEA and HelloDPO as UK/EEA data protection officer — a US vendor with an Article 27 representative, not an EU setup. Transfers rest on the EU-US Data Privacy Framework and standard contractual clauses; we found no EU hosting option, and the privacy policy points to a subprocessor list that the captured pages do not show. 3 4
The Skeptic
A United States contracting entity (ZenLeads Inc., Covina, California) that collects, processes and stores personal information in the United States and other countries, with an EEA representative (Lionheart Squared), a UK/EEA Data Protection Officer, transfers papered with EU-US Data Privacy Framework certification and Standard Contractual Clauses, and a subprocessor list said to be available. That is the non-EU-entity-with-EU-representative pattern; we found no public information on EU hosting or an EU controller for the database of EU residents. 3 4
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.
5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.
8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.
10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.
The SDR Team Lead
Prices are largely computable from public pages: $0 with 900 credits granted monthly, $49 Per seat per month, billed annually with 30,000 credits, $79 with 48,000, and $119 with a 3-seat minimum and 72,000, credits expiring at the end of the billing cycle with no rollover, taxes excluded, annual billing saving 24%, and the Advanced Dialer and Inbound add-ons each at $119 Per team, per month billed annually. What I cannot compute: credits per data type such as mobile versus email are referenced to a linked conversions page rather than shown, and we found no public information on overage rates or refunds for inaccurate data — subscriptions are nonrefundable. 2 4
The RevOps Manager
All four tiers are priced per seat with annual credit allowances granted upfront, credit expiry is explicit (end of billing cycle, no rollover), both add-ons carry prices, and auto-renewal, non-refundability, per-user seat rules and taxes-excluded are all stated. What I cannot compute is what a credit buys: the credit conversion rates per data type sit on a separate page the terms only point to, and I found no public information on overage rates or API pricing. 2 4
The Data Protection Officer
All four tiers are public with per-seat prices and annual credit allowances granted upfront, credit expiry with no rollover is stated in the terms, seats are per-user with no decrease mid-term, add-ons are priced at "$119 Per team, per month billed annually", taxes are excluded and auto-renewal with 30 days' notice is documented. What a credit buys per data type sits on a credits page we can only see referenced, and we found no public information on overage rates or API pricing — with subscriptions non-cancelable and non-refundable in all cases. 2 4
The ABM Marketer
All four tiers are public with per-seat prices and credit allowances, credit expiry with no rollover is stated, the visitor-identification and dialer add-ons are priced, and tax treatment, auto-renewal and minimum commitment are on the pages. What keeps the annual invoice from being computable is that the captured pages never say what a credit buys by data type — the terms point to a separate credit-conversion page — and I found no public information on API access or overage pricing. 2 4
The DACH Sales Director
Every tier is public with credit allowances — $0 with 900 credits per seat per year, $49 Per seat per month billed annually with 30,000, $79 with 48,000, $119 with 72,000 and a three-seat minimum — alongside add-ons at $119 per team per month, no credit rollover, per-seat pricing and "Prices exclude any applicable taxes". What a credit buys per data type sits on a separate credits page, and we found no public information on overage rates or any refund for inaccurate data, with the terms making subscriptions nonrefundable. 2 4
The Skeptic
Tier prices with credit allowances, per-seat costs, credit expiry with no rollover, the no-refund stance, auto-renewal notice, seat rules, currency, net-30 terms and tax treatment are all public and unusually explicit — including the Inbound and Advanced Dialer add-ons at $119 per team per month. What a credit buys is not on the captured pages: no credits-per-data-type figures for email, phone or mobile numbers, and no API or overage rates, so the annual invoice for a given export volume cannot be computed from these pages alone. 2 4
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 24 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 17 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 8 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 support fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (11)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.apollo.io Checked 22 Sep 2026 Details →
- 2 Pricing page www.apollo.io Checked 22 Sep 2026 Details →
- 3 Privacy policy www.apollo.io Checked 22 Sep 2026 Details →
- 4 Terms of service www.apollo.io Checked 22 Sep 2026 Details →
- 5 Coverage, accuracy & freshness — found from sitemap www.apollo.io Checked 1 Oct 2026 Details →
- 6 Coverage, accuracy & freshness — found from sitemap www.apollo.io Checked 1 Oct 2026 Details →
- 7 Visitor identification & intent signals — found from sitemap www.apollo.io Checked 1 Oct 2026 Details →
- 8 Prospecting workflow & outreach rules — found from sitemap www.apollo.io Checked 1 Oct 2026 Details →
- 9 Prospecting workflow & outreach rules — found from sitemap www.apollo.io Checked 1 Oct 2026 Details →
- 10 CRM sync, enrichment & export — found from sitemap www.apollo.io Checked 1 Oct 2026 Details →
- 11 CRM sync, enrichment & export — found from sitemap docs.apollo.io Checked 1 Oct 2026 Details →